Platform Security Vulnerability Management Lead

Fivetran · Remote

Company

Fivetran

Location

Remote

Type

Full Time

Job Description

From Fivetran’s founding until now, our mission has remained the same: to make access to data as simple and reliable as electricity. With Fivetran, customer data arrives in their warehouses, canonical and ready to query, with no engineering or maintenance required. We’re proud that more organizations continue to leverage our technology every day to become truly data-driven.


About the Role

Fivetran is building data pipelines to power the modern data stack for thousands of companies.

To support building customer trust in our solution, we’re looking for a Platform Security Vulnerability Management Lead to join Fivetran's Security team. In this role you will lead the function of collecting, verifying, and tracking platform security vulnerabilities to remediation.

This work is challenging and diverse as Fivetran is a multi-cloud environment operating on AWS, GCP, and Azure. You will manage a team responsible for selecting security tools to detect issues, establishing processes to handle incoming issue reports, run our vendor-supported penetration testing program, design and manage the analysis and triage process, prioritize issues, and create reports, metrics, and dashboards to motivate the engineering organization to address the findings, ultimately raising our security posture while meeting compliance requirements.

This is a full-time US remote position.

Technologies You'll Use

Bash, Python, JS, BigQuery, Sigma, Looker, Retool, Azure, AWS, GCP, Terraform, Docker, Kubernetes, Github, Buildkite, Sonar, SAST, SCA, DAST, WAF, ASPM, CSP

What You’ll Do

  • Coordinate our semi-annual vendor-led pentesting engagement, including verification of results and pursuit of remediation 
  • Manage both Cloud Infrastructure and Application Security vulnerabilities from a variety of sources: Internal/External Reports, SAST, SCA, Sonar, DAST, Pentesting, Security Scorecard, CSPM, and Incidents
  • Analyze, validate, demonstrate, and adjust severity of vulnerabilities based on actual risk to the organization
  • Document guidance to provide clarity about our vulnerability reporting and remediation processes
  • Refine the secure coding and secure cloud configuration guidance and standards provided to engineers
  • Develop innovative strategies to drive engineering to prioritize fixing issues, from most important to least, while reinforcing best practices in infrastructure, container dependency upgrades and 3rd-party library patching
  • Evaluate, select, and manage effective tools for detecting and managing security vulnerabilities
  • Take a “hands-on” approach to build automated integrations with security tools, as well as solutions to inventory, monitor, and report on vulnerability process maturity to leadership and other stakeholders
  • Assist in shifting the culture toward “security by design” by performing root cause analysis (RCA) on the vulnerabilities and recommending improvements in process and habits to prevent issues from recurring
  • Demonstrate satisfaction of internal policy and compliance requirements for SLAs by tracking metrics such as MTTR, vulnerability escape rate, and other SDLC and/or CI/CD pipeline measurements

Skills We’re Looking For

  • Experience running third party penetration tests from contracting through remediation of findings
  • Experience leading a thriving vulnerability management team and program that includes both Application Security and Cloud Security components
  • Strong analytical skills to determine metrics and reports needed to drive action for both the team and the engineering organization
  • Ability to conduct root cause analysis against vulnerabilities and determine feasible technical solutions
  • Ability to communicate effectively with security and engineering leadership to influence the process and habit changes necessary to address vulnerability findings
  • Technical background and ability to write scripts and code to integrate tool APIs with internal ticketing, ASPM/VM, and CI/CD pipeline tools
  • Collaborative experience working closely with product teams, SRE/DevOps, and software engineers to drive adoption of security mindset into processes and SDLC habits

Bonus Skills​

  • Strong understanding of cloud infrastructure and container vulnerability scanning techniques in multi-cloud environments as well as IaC, containers, CSPM security tools such as Lacework, Trivy, Prisma, Qualys, StackRox, AquaSec, Twistlock.
  • Ability to manage and perform triage/validation of Application Security vulnerabilities, including those found in the OWASP Top 10 and the Application Security Verification Standard (ASVS)
  • Experience with cloud-native container deployment architecture (Kubernetes, Docker, GKE, EKS, AKS) and IaC automation tools (CloudFormation, Terraform, Ansible, Chef, Puppet or Lambda)

#LI-REMOTE #LI-RS1

The pay range displayed on this job posting reflects the minimum and maximum target for new hire salaries for the target position and level. Our pay ranges are determined by role, level, and location. Our job titles may span more than one career level. Within the range, individual pay is determined by additional factors, including job-related skills, experience, relevant education or training, business need, market demands. The pay range is subject to change and may be modified in the future. Your recruiter can share more about the specific pay range for your location during the hiring process.


This range represents base salary only and does not include incentive for sales roles, equity, or  benefits, if applicable. 

Pay Range
$191,111—$238,889 USD

 

Perks and Benefits

  • 100% employer-paid medical insurance*
  • Generous paid time-off policy (PTO), plus paid sick time, inclusive parental leave policy, holidays, and volunteer days off
  • RSU stock grants
  • Professional development and training opportunities
  • Company virtual happy hours, free food, and fun team building activities
  • Monthly cell phone stipend
  • Recharge, reenergize, and pursue personal and professional goals with a 30 day paid leave after 5 years

*may vary by country - please reach out to your recruiter for more information


To learn more about Fivetran's benefits by region - click here.

We’re honored to be valued at over $5.6 billion, but more importantly, we’re proud of our core values of Get Stuck In, Do the Right Thing, and One Team, One Dream. Read about us in Forbes.     

Fivetran brings together high-quality talent across the globe to make data access as easy and reliable as electricity for our customers. We value and recognize that our customers benefit from having innovative teams made of people from many backgrounds, experiences and identities. Fivetran promotes diversity, equity, inclusion & belonging through attracting, recruiting, developing and retaining a diverse workforce, not only because it is the right thing to do, but because it helps us build a world-class company to better serve our customers, our people and our communities.

To learn more about Fivetran’s culture and what it’s like to be part of the team, click here and enjoy our video.

To learn more about our candidate privacy policy, you can read our statement here.

Apply Now

Date Posted

08/08/2023

Views

19

Back to Job Listings Add To Job List Company Profile View Company Reviews
Positive
Subjectivity Score: 0.8

Similar Jobs

Senior Product Designer - Org & Security - Typeform

Views in the last 30 days - 0

This job description outlines a role in developing an intelligent contact management system with AI capabilities The position involves designing user ...

View Details

Senior Design Manager (Infrastructure) - Canonical

Views in the last 30 days - 0

Canonical a leading opensource provider seeks a Senior Design Manager to drive innovation in cloud and AI technologies The role offers remote work glo...

View Details

Executive Director Patient Advocacy - Kyverna Therapeutics

Views in the last 30 days - 0

Kyverna Therapeutics is seeking an Executive Director for Patient Advocacy to lead initiatives in autoimmune disease treatment The role involves build...

View Details

Medical Affairs Writer Contract - Kyverna Therapeutics

Views in the last 30 days - 0

Kyverna Therapeutics seeks a Medical Affairs Writer to develop scientific publications and communications for cell therapy innovations The role requir...

View Details

Product Manager Wallet SDKs - Startale

Views in the last 30 days - 0

The text describes a job alert system where applicants must mention UNSELFISH and use a specific tag to demonstrate they read the post It explains the...

View Details

Recovery Analyst Underpayments - Trend Health Partners

Views in the last 30 days - 0

TREND Health Partners seeks an Underpayment Recovery Analyst to optimize client reimbursement through collaboration and detailed claim analysis The ro...

View Details